Part of the AI Regulation News hub.
China has put out for comment a non-binding draft practice guide that would call for separate user consent before in-car voice dialogue records are used to train models, and would say a refusal should not affect use of the voice-dialogue function
The phrase artificial intelligence never appears in this draft. It defines and regulates a voice system with multi-turn context understanding and a camera-based driver-monitoring system using on-board intelligent algorithms.
Bottom line: Not binding and not final. This is a TC260 practice guide, a technical document rather than a national standard or a regulation, and it is out for public comment. Nothing here obliges anyone yet.
What it would do: The draft says using a user's dialogue records for model training and product optimisation should require their separate consent and anonymisation, and that a refusal should not affect their use of the voice-dialogue function. It says wake-word data should in principle be processed in the vehicle, and that driver-monitoring face data should be processed in the vehicle, with capture-and-discard described as advisable.
Who this affects: Vehicle manufacturers, parts and software suppliers and in-vehicle application providers selling into China, which includes foreign manufacturers, and any voice-service vendor supplying them.
The deadline: Comments are due to the TC260 Secretariat by 3 September 2026 under notice 网安秘字〔2026〕102号.
Primary sources: TC260 consultation notice 网安秘字〔2026〕102号, 20 August 2026 · Draft practice guide TC260-PG-2026NA (PDF)
- Instrument (EN)
- Cybersecurity Standard Practice Guide: Cabin Data Processing Security Requirements, draft for comment
- Instrument (ZH)
- 网络安全标准实践指南 座舱数据处理安全要求 征求意见稿
- Reference
- TC260-PG-2026NA, draft v1.0-202608; notice 网安秘字〔2026〕102号
- Authority
- Secretariat of the National Information Security Standardization Technical Committee (TC260)
- Jurisdiction
- China
- Date
- Notice and draft dated 20 August 2026
- Status
- Open public consultation. Comments due 3 September 2026.
- Bindingness
- None. A practice guide is a technical document, not a GB national standard and not a regulation, and this one is still a draft.
- Primary source
- The draft guide itself, read in full
- Primary source
- https://www.tc260.org.cn/portal/article/2/66ab0e249d404f0583bc420b6106f899
What this is, and what it is not
On 20 August 2026 the secretariat of China's national cybersecurity standards committee opened a public consultation on a draft practice guide covering the security of cabin data processing. Comments are due by 3 September 2026.
Take the status seriously before reading anything into the content. A practice guide is a technical document the secretariat issues to give standardisation guidance. It is not a GB national standard and it is not a regulation. This one is also a draft. Nothing in it obliges anyone today, and the final text may differ.
It is still worth reading, because drafts of this kind are where the expectations that later harden get written down, and because the substance is unusually concrete.
The word artificial intelligence never appears, which is not the same as it not being about AI
Search the draft for the Chinese term for artificial intelligence and you will not find it. Search for what it actually describes and the picture changes.
The guide defines intelligent conversation as a function resting on an in-vehicle intelligent voice interaction system, using natural speech as the input and output medium, and supporting multi-turn context understanding and continuous interaction. That is a conversational assistant with memory across turns.
It defines the driver state monitoring system as an in-cabin system that uses on-board intelligent algorithms to identify driver fatigue, distraction and hands-off states in real time from image capture, and to output warnings or vehicle intervention instructions.
So the draft governs a conversational model and a computer-vision system that watches the driver's face. Reporting it as a data-protection document alone would miss what it does.
The training-data provisions are the sharpest part
Two clauses are worth quoting in substance because they are unusually direct about model training.
Where a processor uses a user's intelligent-dialogue records for model training and product optimisation, the draft says it should obtain the user's separate consent and anonymise the records so they cannot be traced to the individual. Separate consent is a specific concept in Chinese data law, distinct from bundled consent to a privacy policy.
The clause that follows is the one that would bite hardest on product design. If a user refuses to let their dialogue records be used for model training and product optimisation, the draft says that refusal should not affect their use of the voice-dialogue function.
Around those sit the ordinary controls: the user should be given a way to switch the assistant on and off, dialogue records should in principle not be retained at all, and where they are retained the processor should say why, where and for how long, and give the user a way to look at them and delete them. Where the voice service comes from a third party, the manufacturer should fix data provision, retention, processing, safeguards and responsibilities by contract.
Wake words, voiceprints and the default that audio stays in the car
The wake-word provisions read like they were written by someone who has thought about how these systems fail.
Audio held temporarily to recognise a wake word should be kept no longer than the minimum needed to do that. Voiceprint data should sit in an independent space in the vehicle and should not be stored alongside identity information. If the microphone opens and no valid command arrives within a preset time, the system should exit collection rather than keep listening.
There should be a mechanism for handling false wakes, and when a wake is judged false the system should leave the voice-interaction state and delete the audio and the process data it generated. Users should be told how false-wake data is transmitted, stored and deleted.
The default direction of travel is inward. Wake data should in principle be processed inside the vehicle. Where it genuinely has to go outside, the draft prefers sending the text needed for the function rather than the audio, and sending raw audio at all would need the user's separate consent.
Driver monitoring, and capture-and-discard
The driver-monitoring clauses are shorter and stricter. The processor should tell the driver where the camera is. The camera's collection should not extend to other people in the car.
Face data collected for driver monitoring should be processed inside the vehicle, and the draft says it is advisable to use capture-and-discard, meaning the frame is used and thrown away rather than stored.
For anyone building or buying these systems, that is the design constraint to notice. A driver-monitoring architecture that ships face data to a server for processing is not what this draft contemplates.
Who is credited with technical support
The draft carries a credit line for technical support from the China Electronics Standardization Institute, Xiaomi Auto, Li Auto, the national computer network emergency response coordination centre, a Shanghai motor vehicle testing and certification institute, Yinwang Intelligent Technology and Beihang University. That is the whole list, research bodies and companies together, and it is printed openly in the document.
Industry participation in standards drafting is routine everywhere, at ISO, at IEEE and in China's own GB process, so the presence of vehicle and technology firms among the contributors is unremarkable in itself. It is worth knowing only because it tells a reader where the engineering knowledge behind the text came from.
We can say no more than the document says. The credit is for technical support. We do not know what any named organisation proposed, drafted or objected to, and we are not suggesting otherwise.
What we did not verify
We read the draft guide in full, twelve pages, and the consultation notice. Every provision described above comes from that text.
We did not verify GB/T 41871-2022, the standard the draft cites as the source of its cabin-data definition. We report only that the draft cites it.
We did not confirm what role any named supporting organisation actually played beyond the credit line printed in the draft, and we did not contact any of them.
We did not establish whether an earlier version of this practice guide exists, or what the secretariat intends to do with the comments it receives. A practice guide is not on a legislative timetable and we can point to no date on which any of this would take effect.
We have translated the operative provisions rather than quoting them in English as though the draft were written that way. Where the distinction matters we have kept the draft's own hedging, including the difference between what it says should be done and what it says is advisable.
Nothing here binds anyone yet, and it may never bind anyone in this form. What it shows is the shape China's standards side is proposing for in-car systems: training on a user's dialogue records should need their separate consent, a refusal should not affect their use of the function, and both voice and face data should be handled inside the car rather than shipped out of it. If you sell vehicles or in-car voice services into China, the comment window closes on 3 September 2026.
Source File
https://www.tc260.org.cn/portal/article/2/66ab0e249d404f0583bc420b6106f899
Open the TC260 notice 网安秘字〔2026〕102号 of 20 August 2026 and download the attached draft, TC260-PG-2026NA. Read clause 5.2 for the voice-dialogue provisions, in particular 5.2(d) on separate consent for model training and 5.2(e) on refusal not affecting the function, clause 5.1 for the wake-word and voiceprint rules, and clause 5.3 for driver monitoring and the capture-and-discard language. Note the server serves the file with a content type that defeats browser PDF viewers, so download it and open it locally.
用户拒绝将对话记录用于模型训练和产品优化的,不应影响智能语音对话功能使用 · TC260-PG-2026NA, clause 5.2(e), draft for comment, 20 August 2026
FAQ
Does this draft require my company to do anything?
No. It is a TC260 practice guide, which is a technical guidance document rather than a national standard or a regulation, and it is still a draft out for public comment until 3 September 2026. It creates no obligation now.
What would it change about training models on in-car voice data?
It would ask cabin data processors to obtain the user's separate consent before using intelligent-dialogue records for model training and product optimisation, and to anonymise those records so they cannot be traced back to the person. Separate consent is a distinct concept in Chinese data law and is not satisfied by a bundled privacy policy.
What happens if a user refuses to let their data train the model?
The draft says a user's refusal to have dialogue records used for model training and product optimisation should not affect their use of the voice-dialogue function. It is guidance rather than a prohibition, but it is the provision most likely to constrain product design if the guide is finalised in this form.
Does it apply to foreign manufacturers selling in China?
It is addressed to cabin data processors, which the draft defines as vehicle manufacturers, parts and software suppliers and in-vehicle application service providers. Nothing in the definition turns on where the company is incorporated, so a foreign manufacturer selling into China would fall within its scope on the same terms, subject to the point that the guide binds nobody at present.
Related briefings
Sponsored Training
Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.